The AI-tool register for small teams

Bring workplace AI use into the open.

Your team already uses AI tools. ToolRoster is the register that says which ones are approved, what data is allowed in them, and who signed off — without surveillance.

No prompts read · No tracking · 10-minute setup

RegisterAcme Agency · Sheet 01
ToolStatus
01ChatGPT
OpenAI
Approved
02GitHub Copilot
GitHub
Restricted
03Otter.ai
Otter.ai
Blocked
04Midjourney
Midjourney
Under Review
05Perplexity
Perplexity AI
Requested
5 tools on registerUpdated today
81%of employees use AI tools their company never approvedUpGuard, State of Shadow AI
77%of AI-using small businesses have no written AI policyU.S. Chamber research
$670kadded breach cost when shadow AI is involvedIBM breach-cost research
§01The problem

Shadow AI isn't a discipline problem. It's a visibility problem.

Bans push usage underground — nearly half of employees say they'd keep using banned tools anyway. The teams that get this right don't spy on anyone. They publish a register everyone can see, make requesting a tool easier than sneaking one, and keep receipts. That register is the whole product.

§02What's in the register

A simple operating system for approved AI usage

01

One register, five statuses

Approved, Restricted, Blocked, Under Review, Requested — plus an explainable risk level scored from the vendor facts you record.

02

Data rules per tool

Spell out what can and can't be pasted into each tool — customer data, source code, PII — in plain labels everyone reads the same way.

03

Requests instead of secrets

Employees request new tools in a minute. Admins approve, restrict, or block — every decision recorded, nothing underground.

04

Policy people actually read

A plain-English AI usage policy with versioning and one-click acknowledgments. See exactly who has read what.

05

Audit-ready, scored

A readiness score tells you exactly what to fix before a client questionnaire, audit, or insurance form lands — then a one-file evidence pack to send when it does.

06

A public approved-tools page

Share a clean page of approved tools with your team or clients. No login needed — trust as a marketing surface.

§03The operating loop

Request. Decide. Acknowledge.

01 — Request

Someone wants a tool

They file a one-minute request: what it is, what it's for, what data would go in. It lands on the register as Requested.

02 — Decide

An admin rules on it

Approve, approve with restrictions, or reject and block. The decision, the reasoning, and the data rules are recorded.

03 — Acknowledge

The team signs off

Everyone acknowledges the usage policy. You can prove it — to a client, an auditor, or an insurance form — in one export.

§04What ToolRoster is not

Not enterprise GRC.
Not endpoint surveillance.
Not an AI firewall.

We don't read prompts, track browsing, or watch your employees. ToolRoster works because it's easy to adopt and easy to trust — surveillance just pushes AI use back into the shadows.

§05Questions

What teams ask before they start

Does ToolRoster read prompts or monitor employees?
No. ToolRoster does not connect to your AI tools or intentionally collect AI prompts, external browsing history, or private employee activity outside ToolRoster. It records actions inside the service because registry changes, requests, decisions, acknowledgments, and administrative events form the audit trail.
Isn't this just a spreadsheet?
It starts where a spreadsheet stops: a request-and-approval flow, policy acknowledgments you can prove, an explainable risk level per tool, review reminders, and a one-click evidence pack for audits and questionnaires.
How is a tool's risk level calculated?
Deterministically, from the vendor facts you record — whether a tool trains on your data, offers SSO, has a DPA, and what data you allow into it. Every risk level traces to a named signal. There is no AI guessing.
Does it help with the EU AI Act, SOC 2, or security questionnaires?
It produces the artifacts those ask for: an AI tool inventory with risk classification, per-tool data rules, and acknowledgment records, exportable as a single evidence pack. A readiness score flags the gaps to fix before you send it. (ToolRoster is a tool, not legal advice.)
Is it really free?
Yes. The free plan covers one workspace and up to 10 tools, including the request workflow, policy, public page, and CSV exports. Paid plans add more tools and team and compliance features.
Who builds ToolRoster?
ToolRoster is built by Eastbase Studio, a small independent software studio. Your data is portable — registry history and exports are never paywalled retroactively.

Set up your registry in 10 minutes.

Start from the tool catalog, publish your policy from the template, and share the public page with your team today.

Free plan · No credit card · 10 tools